![]() |
| |||||||
Log-Analyse und Auswertung: Firefox öffnet neue FensterWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| | Firefox öffnet neue Fenster Hallo Chris C:\Program Files\Ask.com\GenericAskToolbar.dll habe ich gelöscht. Prevx hat nichts gefunden! Gmer: GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-03-14 20:34:36 Windows 6.0.6002 Service Pack 2 Running: pnjeobuc.exe; Driver: C:\Users\BENJAM~1\AppData\Local\Temp\ugrdipow.sys ---- User code sections - GMER 1.0.15 ---- .text C:\Windows\Explorer.EXE[2176] SHELL32.dll!SHGetFolderPathAndSubDirW + 81C9 7692B364 4 Bytes [50, 26, 00, 10] {PUSH EAX; ADD ES:[EAX], DL} ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [746E7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7473A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [746EBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [746DF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [746E75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [746DE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74718395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [746EDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [746DFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [746DFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [746D71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [7476CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7470C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [746DD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [746D6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [746D687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [746E2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [100027E0] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibraryAndExitThread] [10001B60] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [10002B60] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Windows\Explorer.EXE[2176] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [100011D0] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Program Files\iTunes\iTunes.exe[5280] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [098B2B60] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Program Files\iTunes\iTunes.exe[5280] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [098B11D0] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Program Files\iTunes\iTunes.exe[5280] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateThread] [098B27E0] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) IAT C:\Program Files\iTunes\iTunes.exe[5280] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FreeLibraryAndExitThread] [098B1B60] C:\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll (Acer eDataSecurity Management PSD DragDrop Protection/Egis Incorporated) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) ---- Files - GMER 1.0.15 ---- File C:\Program Files\Prevx 0 bytes File C:\Program Files\Prevx\prevx.exe 6300592 bytes executable ---- EOF - GMER 1.0.15 ---- |
| | #2 |
![]() ![]() ![]() ![]() ![]() | Firefox öffnet neue Fenster Hi,
__________________ein Rootkit scheint es nicht zu sein... Passiert das auch bei dem IE oder nur im FF? GooredFix Lade dir bitte GooredFix.exe (http://jpshortstuff.247fixes.com/GooredFix.exe) herunter und speichere es auf deinem Desktop. Führe das Programm per Doppelklick aus (Vista/Win7-User als Admin!) und wähle die Option 1. FF muss komplett geschlossen sein! Ein Log sollte sich öffnen, poste den Inhalt bitte hier. OTL Lade Dir OTL von Oldtimer herunter (http://filepony.de/download-otl/) und speichere es auf Deinem Desktop * Doppelklick auf die OTL.exe * Vista/Win7 User: Rechtsklick auf die OTL.exe und "als Administrator ausführen" wählen * Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output * Unter Extra Registry, wähle bitte Use SafeList * Klicke nun auf Run Scan links oben * Wenn der Scan beendet wurde werden 2 Logfiles erstellt * Poste die Logfiles hier in den Thread. chris
__________________ |
![]() |
| Themen zu Firefox öffnet neue Fenster |
| anti-malware, appdatalow, ask toolbar, ask.com, avg free, avg security toolbar, bösartige, ccleaner, current, dateien, explorer, fenster, finds, firefox, gefunde, gereinigt, gupdate, home premium, local, local\temp, malwarebytes, minute, neue, notepad.exe, online, plug-in, pop-up-blocker, problem, programdata, safer networking, service, software, start menu, temp, update, users, version, verzeichnisse, vollständiger, wscript.exe, öffnen, öffnet |